Deploy and Connect the Sophos NDR Investigation Console
The NDR Investigation Console provides local access to sensor data that is not transferred in full to the Sophos Data Lake. It is configured in Sophos Fusion but runs as a separate VM on the local network. It receives its data from an existing NDR Integration Appliance.
Quick procedure: Check the requirements, create the console under My Products > NDR > Investigation Console, securely store the zadmin password that is displayed once, deploy the generated image on VMware ESXi or Microsoft Hyper-V, wait for the Connected status, assign one or more healthy NDR Integration Appliances, and verify initial local access.
Scope: This runbook does not install an NDR sensor, configure traffic mirroring, or cover the analysis of detections, Cases, or cloud data. The Investigation Console is a separate VM; its status proves neither the health of the NDR sensor nor the completeness of its SPAN coverage. Deleting the console or its data and fully decommissioning it remain out of scope.
1. Check prerequisites and responsibilities
Before deployment, all of the following requirements must be met:
- The tenant already has an NDR integration with at least one assignable NDR Integration Appliance. Before assignment, identify the intended appliances in the appliance inventory and check their health. “Deploy Sophos NDR on VMware ESXi or Hyper-V” describes their separate deployment and initial registration.
- The NDR entitlement has been confirmed. Sophos generally requires the Sophos Network Detection and Response integration license pack. The only documented exception is for MSP Flex customers: with an XDR licence, Sophos NDR does not require an additional Integration License Pack. “Set up MDR and XDR integrations in Sophos Fusion” covers the overall integration workflow and the boundaries between integration types.
- The person performing the work needs a role that permits Create console, Download image, Assign Appliance, and Open NDR Console. Test in advance which predefined or custom role includes these actions in the affected tenant; no standalone minimum NDR role is documented.
- Sophos Fusion uses a current, supported desktop browser: Google Chrome, Microsoft Edge, Mozilla Firefox or Apple Safari on macOS. Mobile devices are not used.
- The target platform is VMware ESXi or Microsoft Hyper-V. Other platforms are not documented as supported for Investigation Console.
- A responsible person has access to Fusion, the hypervisor, the management network, DNS, DHCP/IPAM, and the outbound firewall or web proxy.
- An approved password system is ready for the
zadminpassword, which is displayed only once. The password must not be placed in change tickets, screenshots, chat, or email.
zadmin is a local account on the console appliance, not a Sophos Fusion or MDR account. The Fusion role, hypervisor permissions, and local console access must therefore be approved and managed separately.
Do not derive the console VM resources from the NDR sensor’s minimum requirements. The Hyper-V script prompts for CPU and memory. Use only values approved for the Investigation Console by Sophos or the platform owners. If no such specification is available, stop deployment before entering these values and clarify the sizing.
2. Decide on the management network
The console VM requires a stable management address and internet access. It does not need a SPAN connection for this deployment; plan and accept sensor mirroring separately by following “Plan and Validate Traffic Mirroring for Sophos NDR”. Record the following before creating the console:
- Management VLAN or port group or vSwitch;
- addressing type DHCP or Manual;
- a reserved address for DHCP or an available static address for Manual;
- subnet mask, default gateway, and reachable DNS servers;
- outbound internet path and, where applicable, web proxy;
- administration network from which the local console must be reachable.
DHCP is permitted only if the assigned address is reserved. This keeps the hypervisor mapping, local access rules, and operational documentation stable.
For Manual, enter the network values displayed in Fusion according to the approved IP plan. Before saving, check whether the IP address is free and whether routing, gateway and DNS are reachable.
3. Configure console in Sophos Fusion
- Open in Sophos Fusion My Products > NDR > Investigation Console.
- Click on Create console.
- Fill in the visible fields:
- Name: unique, operational name, for example
ndr-console-zrh-01; - Description: location, responsible entity and purpose without access data;
- Virtual platform: VMware ESXi or Microsoft Hyper-V;
- Configure Internet facing network port settings: management interface with DHCP or Manual.
- Name: unique, operational name, for example
- Save with Save.
- In the Appliance Credentials dialog, enter the username
zadminand the displayed password directly into the shared password system. - Check the entry in the password system and only then select Ok.
The password is displayed only once and cannot be retrieved from Fusion later. Do not “secure” it by taking a screenshot. If secure storage has not been confirmed, do not download or deploy the image.
The new console appears first with Waiting for deployment. Image creation can take about five minutes. Once Download image is available, download the image from the three-point menu and place it in a protected working directory.
4. Deploy the image
VMware ESXi
The OVA is verified by Sophos Fusion and can only be used once. For a new VM, a new OVA must therefore be generated in Fusion; an already used OVA is not a recovery image.
- Open on the ESXi host Virtual Machines > Create/Register VM.
- Under Select creation type, select Deploy a virtual machine from an OVF or OVA file and click on Next.
- Enter a unique VM name under Select OVF and VMDK files, click Click to select files … and select the downloaded OVA. Continue with Next.
- Under Select storage, select the storage type Standard and then select the intended data store. Click Next.
- Configure under Deployment options:
- for MGMT, select the management port group defined in Section 2;
- under Disk Provisioning select the option Thin;
- Activate Power on automatically.
- Click on Next, skip Additional settings without any additional changes and finish with Finish.
- Wait until the VM appears in the list. Then reconcile the assignment of MGMT with the documented configuration and start the VM.
For DHCP, the selected port group must reach the DHCP server and the reservation must be active. A SPAN or mirror network shall not be used as MGMT.
Microsoft Hyper-V
The ZIP contains the virtual drives, seed.iso and the PowerShell script ndr-sensor.ps1. Do not change the filename of the script supplied by Sophos; its name does not mean that this runbook deploys a sensor.
- Unpack the ZIP into a local, protected folder on the Hyper-V host. Do not mix the included files with files from an older download.
- Start
ndr-sensor.ps1with right click and Run with PowerShell. - If Security Warning appears, check the origin and make sure the file came from the download you just created. Then allow the local file with Open.
- Answer the script’s questions:
- Enter a unique VM name;
- check the displayed new folder in the default path for virtual drives and create it with
C; - enter the approved number of processors;
- enter the approved memory in GB;
- select the vSwitch for the management interface from the numbered list.
- For the packet-capture vSwitches requested by the script, select an existing vSwitch as a placeholder. The Investigation Console does not use these adapters for packet capture; disconnect them individually in the VM settings after the VM is created successfully. Leave the management adapter connected.
- Wait for Installation Completed Successfully and close the script by pressing any key.
- Open the new VM in Hyper-V Manager. Check the VM name, CPU, RAM, virtual drives, connected management vSwitch, and disconnected packet-capture adapters. Then start the VM.
5. Wait for initial start and registration
On the first start, the VM checks the management connection and the Internet access and then restarts automatically. This process can take up to ten minutes.
- Do not interrupt the initial start and the automatic restart by manually turning it off or on.
- Check the VM console for a start or restart loop.
- For DHCP, compare the actual assigned address with the reservation; for Manual, check the planned address.
- In Fusion My Products > NDR > Investigation Console open and wait until the status Connected is displayed.
Connected confirms registration of the console VM with Sophos Fusion. It does not yet confirm that an NDR integration appliance is assigned or delivers data to the console.
6. Assign NDR Integration Appliances
Appliances can be assigned only after the console is registered with Fusion and shows a green status. Under My Products > NDR, verify beforehand that every intended appliance is unambiguously identified and has no unresolved health issue.
- On My Products > NDR > Investigation Console, search the new console in the list.
- Open the three-point menu on the right and select Assign Appliance.
- Select one or more NDR integration appliances based on their unique names.
- Save with Save.
- Expand the arrow next to the console name and verify the assignment.
Expand the console entry and check its name, version, IP address, and all assigned appliances. Do not confuse the console IP address with the appliances’ management IP addresses.
7. Check local first access
- Under My Products > NDR > Investigation Console open the three-point menu of the console.
- Select Open NDR Console.
- Confirm the notice that you are leaving Sophos Fusion.
- Enter
zadminand the password stored in the password system. - Continue with Open Console.
Initial access is successful if the browser opens the local Investigation Console and accepts the login. After that, log off again and only document the success, time, name of the console and the safe entry used – never the password.
8. Record acceptance
Deployment is complete only when all of the following conditions are met:
- The right console VM runs on the chosen platform and has the expected management address.
- Fusion shows for the console Connected.
- Type, Version, CPU, Memory and IP Address are plausibly displayed.
- Appliances shows the expected number; the expanded row lists all intended NDR Integration Appliances.
- Open NDR Console leads to the local login and
zadmincan log in with the securely stored password. - The password is only in the shared password system; temporary downloads are still protected.
- Time, tenant, console name, platform, management IP, assigned appliances and test result are recorded in the change documentation.
This acceptance confirms deployment, registration, assignment, and access. It does not confirm complete sensor data coverage and does not replace an approved detection or threat-hunting test.
9. Isolate errors by symptom
Image remains on Waiting for deployment
- Wait up to five minutes for image creation and then reload the page.
- Check if Save was successful and the correct console entry is open.
- Do not create a second console with the same purpose in parallel.
- If Download image remains unavailable, record the console name, tenant, time, and status for Sophos Support.
VM starts, but Fusion does not show Connected
- Wait for the first start and automatic restart for up to ten minutes without interruption.
- Check the operating state and VM console for a recurring start loop.
- Check the MGMT assignment or management vSwitch.
- Compare the DHCP lease and reservation, or the manual network values, with the approved plan.
- Check DNS, the default gateway, the internet path, and the web proxy from the management network.
- Make only one change at a time, then check the status again.
Assign Appliance is not available
- The console must be registered and show green status.
- Check whether the role used to perform the work actually permits the action.
- Ensure that an existing NDR integration appliance can be selected.
Open NDR Console does not reach the local site
- Compare IP Address in the console list with DHCP/IPAM and VM configuration.
- Check routing and network path from the administration device to the console local address.
- Ensure that no SPAN or isolated vSwitch for packet capture has been connected as MGMT.
- Use a supported current desktop browser and confirm the change from Sophos Fusion displayed when opened.
- Do not create a broad firewall rule from
AnytoAnyas a test.
zadmin password missing or rejected
The original password cannot be displayed again. In Fusion, open My Products > NDR > Investigation Console, select the affected console, open the three-point menu on the right, and select Generate New Password. Copy the new password immediately into the password system, check the secure storage and only then click on Reset.
Document the reset as a credential change. Do not record old passwords in tickets or reuse them.
Connected and assigned, but no expected data
First, verify the console name and all assigned appliances. Then check each affected NDR Integration Appliance separately for health and data delivery by following “Monitor Sophos NDR Health and Capacity”. Changes to SPAN, the sensor, or cloud analysis do not “repair” the console VM. Without a confirmed registration or assignment fault, do not rebuild the management network or assign another appliance speculatively.
10. Abort and retry
The following steps deal only with the newly deployed console VM. They do not replace a complete removal or offboarding procedure:
- Do not assign an appliance in case of an error before Assign Appliance. Secure status, VM console, network assignment and timestamp.
- Do not assign an additional appliance after the assignment and do not change an existing NDR integration. Document the status and current assignment.
- Shut down the newly deployed console VM in the hypervisor if it is unstable, has incorrect management values, or the deployment must be aborted. First make sure that the new console VM is actually selected.
- Disable newly created management access rules or DHCP reservations used exclusively by this VM only through the normal change process. Leave shared port groups, vSwitches, DNS servers, gateways, and firewall objects unchanged.
- Do not delete the console entry, assigned NDR Integration Appliance, VM files, or downloaded image. Do not infer an unassignment or removal procedure from a visible menu action; it requires a separately validated decommissioning workflow.
- Generate a new OVA in Fusion for another ESXi attempt. Do not reuse the OVA from the previous attempt.
This keeps the existing NDR environment unchanged. Before another attempt, review the cause, management network, permissions, and image assignment.